4 ms·
> If IP addresses were considered PII, then no routers database or Whois registries could legally exist, which would mean to a larger extent Internet routing co
by robbya 7y ago
> If IP addresses were considered PII, then no routers database or Whois registries could legally exist, which would mean to a larger extent Internet routing could not exist as we know it.
I think this statement is misinformed. There are countries that have rules around protecting PII. WHOIS implementations have changed as a result, but I think these laws have carve outs that allow routers to function. The laws are more nuanced than this.
Examples:
ICANN adopted tiered access for gTLD registration information: https://www.icann.org/resources/pages/gtld-registration-data-specs-en https://www.icann.org/resources/pages/gtld-registration-data...
EU courts believe that IP addresses, even dynamic IP addresses, can indirectly identify a person: http://curia.europa.eu/juris/document/document.jsf?text=&docid=184668&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=1034974 http://curia.europa.eu/juris/document/document.jsf?text=&doc...
GDPR, however has a carve out that I think permits use by internet routers. One legal justification is:
> Processing is necessary to satisfy a contract to which the data subject is a party.
If my ISP doesn't announce my IP address, then they can't connect me to the internet, which I pay them to do.
- lpellegr 7y agoThanks for the links. > If my ISP doesn't announce my IP address, then they can't connect me to the internet, which I pay them to do. Indeed, it's more nuanced and that's the message that we try to give here. As long that you do not use IP geolocation to identify an individual by itself, it seems to be a legitimate use.